CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30448
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic Slider by Supsystic allows Stored XSS.This issue affects Slider by Supsystic: from …

Mar 29, 2024
CVE-2024-30447
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative Solutions Creative Image Slider – Responsive Slider Plugin allows Reflected XSS.This issue …

Mar 29, 2024
CVE-2024-30446
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: …

Mar 29, 2024
CVE-2024-30445
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab, Inc. Web Icons allows Stored XSS.This issue affects Web Icons: from n/a …

Mar 29, 2024
CVE-2024-30444
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zionbuilder.Io WordPress Page Builder – Zion Builder allows Stored XSS.This issue affects WordPress …

Mar 29, 2024
CVE-2024-29640
9.8 CRITICAL

An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the …

Mar 29, 2024
CVE-2024-25944
5.7 MEDIUM

Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to …

Mar 29, 2024
CVE-2023-49234
6.3 MEDIUM

An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate …

Mar 29, 2024
CVE-2023-49232
9.8 CRITICAL

An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the password reset PINs of administrative users.

Mar 29, 2024
CVE-2024-30645
8.0 HIGH

Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.

Mar 29, 2024
CVE-2024-30521
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Landingi Landingi Landing Pages.This issue affects Landingi Landing Pages: from n/a through 3.1.1.

Mar 29, 2024
CVE-2024-30518
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.

Mar 29, 2024
CVE-2024-30514
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affects Paid Memberships Pro …

Mar 29, 2024
CVE-2024-30513
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.

Mar 29, 2024
CVE-2024-30511
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.45.1.

Mar 29, 2024
CVE-2024-30492
4.3 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from …

Mar 29, 2024
CVE-2024-30482
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Brice CAPOBIANCO Simple Revisions Delete.This issue affects Simple Revisions Delete: from n/a through 1.5.3.

Mar 29, 2024
CVE-2024-30477
5.3 MEDIUM

Missing Authorization vulnerability in Klarna Klarna Payments for WooCommerce.This issue affects Klarna Payments for WooCommerce: from n/a through 3.2.4.

Mar 29, 2024
CVE-2024-30469
5.3 MEDIUM

Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

Mar 29, 2024
CVE-2024-30247
10.0 CRITICAL

NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows …

Mar 29, 2024
CVE-2024-30246
7.6 HIGH

Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could exploit this issue on purpose to delete …

Mar 29, 2024
CVE-2024-29904
7.5 HIGH

CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by …

Mar 29, 2024
CVE-2024-29901
4.8 MEDIUM

The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session …

Mar 29, 2024
CVE-2024-29900
7.5 HIGH

Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb …

Mar 29, 2024
CVE-2024-29686
7.2 HIGH

Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages …

Mar 29, 2024
CVE-2023-49231
9.8 CRITICAL

An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.

Mar 29, 2024
CVE-2024-3081
3.5 LOW

A vulnerability was found in EasyCorp EasyAdmin up to 4.8.9. It has been declared as problematic. Affected by this vulnerability is the function Autocomplete of …

Mar 29, 2024
CVE-2024-30508
6.5 MEDIUM

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

Mar 29, 2024
CVE-2024-30507
2.7 LOW

Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.

Mar 29, 2024
CVE-2024-30506
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Stored XSS.This issue affects All In …

Mar 29, 2024
CVE-2024-30505
6.5 MEDIUM

Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.18.

Mar 29, 2024
CVE-2024-30504
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through …

Mar 29, 2024
CVE-2024-30502
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through …

Mar 29, 2024
CVE-2024-29893
6.5 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server …

Mar 29, 2024
CVE-2024-29890
8.8 HIGH

DataLens is a business intelligence and data visualization system. A specifically crafted request allowed the creation of a special chart type with the ability to …

Mar 29, 2024
CVE-2024-29202
9.9 CRITICAL

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's …

Mar 29, 2024
CVE-2024-29201
9.9 CRITICAL

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible …

Mar 29, 2024
CVE-2024-29024
4.6 MEDIUM

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference …

Mar 29, 2024
CVE-2024-29020
4.6 MEDIUM

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook …

Mar 29, 2024
CVE-2024-28867
5.9 MEDIUM

Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies _un-sanitized string values into metric …

Mar 29, 2024
CVE-2024-28405
7.2 HIGH

SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page …

Mar 29, 2024
CVE-2024-27619
7.3 HIGH

Dlink Dir-3040us A1 1.20b03a hotfix is vulnerable to Buffer Overflow. Any user having read/write access to ftp server can write directly to ram causing buffer …

Mar 29, 2024
CVE-2024-23539
8.3 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to …

Mar 29, 2024
CVE-2024-23538
9.9 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to …

Mar 29, 2024
CVE-2024-23537
8.4 HIGH

Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue.

Mar 29, 2024
CVE-2024-30639
6.5 MEDIUM

Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.

Mar 29, 2024
CVE-2024-30638
4.3 MEDIUM

Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.

Mar 29, 2024
CVE-2024-30637
8.8 HIGH

Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter.

Mar 29, 2024
CVE-2024-30636
6.5 MEDIUM

Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.

Mar 29, 2024
CVE-2024-30635
9.8 CRITICAL

Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.

Mar 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.